News tips Advertise Newsletter
AI · Regulation explainer

Europe delayed its high-risk AI rules. The transparency rules arrived on schedule anyway

The Digital Omnibus on AI moved the hardest compliance deadlines by more than a year. It left the obligations themselves in place, and it did not touch the disclosure duties that now apply to chatbots, deepfakes and AI-generated text.

Key takeaways

  • The Digital Omnibus on AI moved obligations for stand-alone high-risk AI systems, such as those used in hiring, credit scoring and education, from August 2, 2026, to December 2, 2027.
  • High-risk AI embedded in products regulated under Annex I of the Act now has until August 2, 2028.
  • Most Article 50 transparency duties, including telling people they are talking to a chatbot and labeling deepfakes, applied from August 2, 2026, as originally planned.
  • Machine-readable marking of AI-generated content has a grace period to December 2, 2026, but only for systems already on the market before August 2.

For much of the past year, companies that build or use artificial intelligence in Europe were preparing for August 2, 2026, the date when the bulk of the EU AI Act’s rules for “high-risk” systems was due to apply. That deadline has now moved. A package of amendments known as the Digital Omnibus on AI pushed the high-risk obligations back by 16 months for most systems and by two years for others.

The delay has been widely reported. Less widely understood is what did not move. A separate set of transparency obligations, covering chatbots, deepfakes and some AI-generated text, applied on August 2 as originally planned. And the high-risk obligations were deferred, not removed.

How the omnibus came about

The European Commission proposed the omnibus as part of a broader effort to simplify EU digital rules and respond to industry warnings that the technical standards and guidance needed for compliance would not be ready in time. EU institutions reached a provisional political agreement in early May, which member state representatives confirmed in the Council on May 13. According to law-firm summaries of the legislative record, the European Parliament adopted the final text on June 16 and the Council on June 29.

Accounts of the final steps differ by a few days, but the amending regulation was published in the Official Journal and entered into force in late July, shortly before the original August 2 deadline. Several firms identify it as Regulation (EU) 2026/1744.

What moved

The AI Act sorts high-risk systems into two broad groups, and the omnibus treats them differently.

Stand-alone high-risk systems (Annex III). These are AI systems used in sensitive areas listed in the Act, such as employment and worker management, access to credit, and education. A model that screens job applicants or scores loan applicants falls here. Obligations for these systems now apply from December 2, 2027, instead of August 2, 2026.

AI embedded in regulated products (Annex I). These are AI components in products already covered by EU product-safety laws, such as machinery or medical devices. Their obligations now apply from August 2, 2028.

The obligations themselves are unchanged in substance. Providers of high-risk systems will still need risk management, data governance, technical documentation, human oversight and conformity assessment before placing systems on the market. As Gibson Dunn and other firms note, the delay moves the dates; it does not reduce what the rules will require.

The omnibus bought time for the hardest rules. It did not buy time for telling people they are dealing with a machine.

What did not move

Several parts of the Act were already in effect before the omnibus and remain so: the bans on certain prohibited AI practices, the requirement that organizations take steps to ensure staff using AI have adequate AI literacy, and the rules for general-purpose AI models.

The transparency duties in Article 50 are the ones most likely to affect ordinary businesses, and most of them applied in full from August 2, 2026. In plain terms:

  • Chatbots and similar systems that interact with people must be designed so that people are informed they are interacting with an AI system, unless that is obvious from the context.
  • Emotion recognition and biometric categorization systems require that the people exposed to them be informed.
  • Deepfakes, meaning AI-generated or manipulated images, audio or video that resemble real people, places or events, must be disclosed as such by those who deploy them.
  • AI-generated text published to inform the public on matters of public interest must be disclosed as AI-generated, with exceptions where the text has undergone human editorial review and someone holds editorial responsibility.

The one adjustment concerns Article 50(2), which requires providers of generative systems to mark outputs in a machine-readable way so they can be detected as AI-generated. For systems already on the market before August 2, 2026, that duty now applies from December 2, 2026. Systems placed on the market after August 2 had to comply from that date. Commentators have described this as a narrow technical grace period rather than a policy reversal. The Commission published final guidelines on Article 50 days before the August deadline.

Who should care outside Europe

The AI Act applies based on where AI systems are placed on the market or used, not only where a company is based. A U.S. software company selling an AI hiring tool to European employers, or a business whose customer-service chatbot serves people in the EU, can fall within its scope. Analysts writing for U.S. audiences have stressed that the omnibus still leaves American firms facing significant compliance costs, just on a later timetable.

What to do with the extra time

  • Do the transparency work now. If you run a chatbot or publish AI-generated media for EU audiences, the disclosure obligations are already live. Check that the disclosure is clear at the point of interaction.
  • Inventory your high-risk uses. Identify any system that touches hiring, credit, education or other Annex III areas. December 2027 is closer than it looks once procurement and vendor contracts are factored in.
  • Ask vendors for documentation. Most businesses deploy AI rather than build it. The Act puts significant duties on providers, but deployers still need to use systems according to instructions and maintain oversight.
  • Watch for standards and guidance. The delay was largely justified by the need for technical standards. Those, rather than the legal text, will define what compliance looks like in practice.

The same pattern is visible in the United States, where Colorado replaced its own comprehensive AI law this year with a narrower statute focused on disclosure. Regulators on both sides of the Atlantic have moved away from the broadest obligations, at least for now, while keeping rules that tell people when an automated system is involved.

Sources

  1. EUR-Lex, Regulation (EU) 2024/1689 (Artificial Intelligence Act), official text
  2. Gibson Dunn, “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes”
  3. Jones Walker, “Yes, August 2 Still Matters: The EU Approved a High-Risk AI Delay, but Most Transparency Obligations Remain”
  4. DLA Piper, “The Digital AI Omnibus: deferral of high risk AI obligations under the AI Act”
  5. Cloud Security Alliance, “EU AI Act High-Risk Deadline Pushed to December 2027”
  6. Responsible AI Platform, “Article 50 transparency deadline: 2 August 2026”
  7. William Fry, Article 50 transparency briefings
  8. The National Interest, “Why the EU’s AI Omnibus Still Leaves US Firms Facing Steep Costs”